What are the CMMC Level 1 requirements?

Short answer

CMMC Level 1 requires the 15 basic safeguarding requirements of FAR 52.204-21 on every contractor system that holds Federal Contract Information (FCI). Every requirement must be fully met, no POA&M is allowed, and you must self-assess annually, post the result in SPRS and have a senior official affirm compliance. Level 1 (Self) remains an allowed designation under the July 2026 Phase 2 suspension.

Who needs Level 1

Level 1 applies when your systems hold FCI: information not intended for public release that is provided by or generated for the government under a contract. It is the baseline for contractors that do not handle CUI. If you hold CUI, you need Level 2, which also satisfies Level 1 for the same scope.

The Revolutionary FAR Overhaul moved the basic safeguarding clause into FAR Part 40 as 52.240-93, so newer contracts may cite that number instead of 52.204-21.

The 15 requirements

  • Access control (4): limit access to authorized users and devices, limit users to permitted functions, control connections to external systems, and control what is posted publicly.
  • Identification and authentication (2): identify users, processes and devices, and authenticate them before granting access.
  • Media protection (1): sanitize or destroy media containing FCI before disposal or reuse.
  • Physical protection (2): limit physical access, and escort visitors, keep access logs and control keys and badges.
  • System and communications protection (2): monitor and protect your network boundary, and separate publicly accessible systems into their own subnetwork.
  • System and information integrity (4): fix flaws promptly, deploy malware protection, keep it updated, and scan files and systems.

How the assessment works

You assess yourself against the NIST SP 800-171A objectives mapped to each requirement, substituting FCI for CUI. Each requirement is scored MET or NOT MET in its entirety. You enter the level, date, scope, CAGE codes and result in SPRS, and a senior Affirming Official attests to continuing compliance. Both steps must be done before award and repeated every year, and evidence must be kept for six years.

Cost and effort

DoD's regulatory cost analysis in the 32 CFR Part 170 final rule estimates $5,977 per small entity for a Level 1 self-assessment and affirmation, repeated annually, and assumes the 15 requirements are already implemented. Your real effort depends on how many systems hold FCI and whether basics such as unique accounts, patching and visitor logs already exist.

Effect of the Phase 2 suspension

None for Level 1. The July 13, 2026 memo permits only Level 1 (Self) or Level 2 (Self) designations while DoD reviews the program, so Level 1 self-assessments continue exactly as before.

Common follow-up questions

Can I use a POA&M for Level 1?

No. The CMMC rule prohibits a POA&M at any time for Level 1 self-assessments. All 15 requirements must be fully implemented and scored MET before you can post a Level 1 (Self) status and affirm it.

Is CMMC Level 1 the same as FAR 52.204-21?

The security requirements are the same 15. CMMC adds the verification layer: a scored self-assessment against NIST SP 800-171A objectives, SPRS posting, an annual affirmation by a senior official and six-year evidence retention.

If I have Level 2, do I also need Level 1?

No separate assessment is needed. Under 32 CFR 170.16, achieving Level 2 (Self) also satisfies Level 1 (Self) for the same assessment scope, because the Level 2 requirements include the Level 1 safeguards.

Need help with this?

LAN Service Group helps small and mid-size defense suppliers implement the 15 basic safeguarding requirements, run the Level 1 self-assessment and keep evidence ready for the annual SPRS affirmation.

Talk to LAN Service Group (888) 281-7243

Sources